Korean
<< Back
VID 50005
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of QuickTime which is older than 7.7 has been installed on the host. QuickTime versions prior to 7.7 are vulnerable to multiple vulnerabilities.

- A buffer overflow in QuickTime's handling of pict files may lead to an application crash or arbitrary code execution. (CVE-2011-0245)
- A buffer overflow in QuickTime's handling of JPEG2000 files may lead to an application crash or arbitrary code execution. (CVE-2011-0186)
- A cross-origin issue in QuickTime plug-in's handling of cross-site redirects may lead to disclosure of video data from another site. (CVE-2011-0187)
- An integer overflow in QuickTime's handling of RIFF WAV files may lead to an application crash or arbitrary code execution. (CVE-2011-0209)
- A memory corruption issue in QuickTime's handling of sample tables in QuickTime movie files may lead to an application crash or arbitrary code execution. (CVE-2011-0210)
- An integer overflow in QuickTime's handling of audio channels in movie files may lead to an application crash or arbitrary code execution. (CVE-2011-0211)
- A buffer overflow in QuickTime's handling of JPEG files may lead to an application crash or arbitrary code execution. (CVE-2011-0213)
- A heap buffer overflow in QuickTime's handling of GIF files may lead to an application crash or arbitrary code execution. (CVE-2011-0246)
- Multiple stack buffer overflows in QuickTime's handling of H.264 encoded movie files may lead to an application crash or arbitrary code execution. (CVE-2011-0247)
- A stack buffer overflow in the QuickTime ActiveX's handling of QTL files may lead to an application crash or arbitrary code execution. (CVE-2011-0248)
- A heap buffer overflow in QuickTime's handling of STSC atoms in QuickTime movie files may lead to an application crash or arbitrary code execution. (CVE-2011-0249)
- A heap buffer overflow in QuickTime's handling of STSS atoms in QuickTime movie files may lead to an application crash or arbitrary code execution. (CVE-2011-0250)
- A heap buffer overflow in QuickTime's handling of STSZ atoms in QuickTime movie files may lead to an application crash or arbitrary code execution. (CVE-2011-0251)
- A heap buffer overflow in QuickTime's handling of STTS atoms in QuickTime movie files may lead to an application crash or arbitrary code execution. (CVE-2011-0252)

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://support.apple.com/kb/HT4826
http://lists.apple.com/archives/security-announce/2011/aug/msg00000.html

* Platforms Affected:
QuickTime versions prior to 7.7
Microsoft Windows Any version
Recommendation Upgrade to the latest version of QuickTime Player (7.7 or later), available from the Apple Web site at http://www.apple.com/quicktime/
Related URL CVE-2011-0186,CVE-2011-0187,CVE-2011-0209,CVE-2011-0210,CVE-2011-0211,CVE-2011-0213,CVE-2011-0245,CVE-2011-0246,CVE-2011-0247 (CVE)
Related URL 46992,46995,48419,48420,48430,48442 (SecurityFocus)
Related URL (ISS)